CVE-2019-11367: Auo Solar Data Recorder

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

Affected products

  • Auo Solar Data Recorder: before 1.3.0 (fixed in 1.3.0)

Published 2019-06-03. Last modified 2026-06-17.